Privacy Policy

Last updated: July 11, 2026

1. Controller

The controller within the meaning of the GDPR is:
Alexander Burkhard, Münsterlandstraße 68, 10317 Berlin, Germany
Contact: [email protected]

We have not appointed a data protection officer under Article 37 GDPR: we are not a public authority or body (Article 37(1)(a) GDPR); our core activities consist neither of large-scale, regular and systematic monitoring of data subjects (Article 37(1)(b) GDPR) nor, at our current user scale, of large-scale processing of special categories of personal data under Article 9 GDPR within the meaning of that provision (Article 37(1)(c) GDPR); and our number of employees additionally does not reach the threshold under § 38 BDSG. We will re-assess this conclusion if our user base, headcount, or the scale of our special-category processing grows materially.

2. What data we process

2.1 Account data and authentication

2.2 Health and nutrition data

Under Art. 9(1) GDPR this data constitutes a special category of personal data and is processed solely on the basis of your explicit consent (Art. 9(2)(a) GDPR).

2.3 Chat content

2.4 Subscription and Plus data

Payment processing itself runs exclusively via Apple. We receive neither your payment-method data nor your billing status.

2.5 Usage and consumption data

2.6 Server log data

2.7 Administrative access (audit log)

When an authorized administrator (currently exclusively the controller) accesses or modifies your account, health or chat data in the course of support, abuse prevention or security audits, we log this access (time, affected account, action taken). This serves the purpose of evidence and accountability under Art. 32 GDPR.

3. Purposes and legal bases

4. Recipients and processors

To provide the service we use the following processors and third-party services. Data processing agreements pursuant to Art. 28 GDPR have been concluded with all of them, where applicable.

5. Transfers to third countries

Several of the providers named above are based in the USA. Where personal data is transferred there, this is done on the basis of the EU-US Data Privacy Framework, provided the provider is certified, otherwise on the basis of the Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR including supplementary measures.

For users in Switzerland, transfers to the USA are based on the Swiss-U.S. Data Privacy Framework where the provider is certified, otherwise on the Standard Contractual Clauses recognized by the Swiss supervisory authority (FDPIC).

For users in the United Kingdom, transfers to the USA are based on the UK Extension to the EU-U.S. Data Privacy Framework ("UK-U.S. Data Bridge") where the provider is certified, otherwise on the UK International Data Transfer Agreement (IDTA) or its Addendum.

6. Retention periods

7. Cookies and local storage

On our public pages (home, /foods, /blog) we collect cookieless, pseudonymous usage statistics scoped to the individual page visit or session — specifically page views and interaction events such as navigation/call-to-action clicks and App Store link clicks — without storing anything on your device (unless you actively opt out of analytics via ?noph=1, which we remember via a single local flag). No persistent, cross-device identifier is set, a session is never linked beyond the page visit, and the data is not used for cross-site advertising. Processing is EU-hosted via PostHog, reached exclusively through our first-party relay proxy (/relay), which strips your visitor IP address before forwarding it to PostHog. Personalised in-app analytics remain separate and run only with your consent in Settings.

8. AI processing

The nutrition assistant is powered by Google Gemini, a generative AI model. Your chat inputs (text, photo, audio) are transmitted to the Gemini API to generate a response. The AI does not replace medical or nutritional advice; its outputs may be incorrect.

Consent and how logging works: AI processing requires your explicit consent, which you give during onboarding or in Settings and can withdraw at any time. The AI assistant is the primary way food is logged in Dumb Calories; if you decline or withdraw consent, you cannot log new food, but you keep full access to view, export, and delete your existing data.

No training on user data: we use Gemini exclusively via the paid API. Google has contractually undertaken not to use your inputs or the generated responses to train or improve its models.

What Gemini receives per request: your current message, the active day's conversation history, the food entries and nutrition totals already logged for that day, your calorie and macro goals, your effective daily goal, and a compact four-day food recap. Not transmitted: your internal account UUID, your current body weight, raw burned-energy (active-calorie) values, or your basal metabolic baseline.

9. Apple Health / HealthKit

If you enable the HealthKit integration in the iOS app, the app reads active and resting energy (calories burned per day), body weight, height, biological sex and date of birth from Apple Health on your device and sends these values to our servers to calculate your calorie goal and for display in the daily overview. In the other direction, the app writes the body weight you log in the app, and the calories, protein, carbohydrates and fat of your logged meals, back to Apple Health. Apple Health data leaves your device only through this explicit activation. You can revoke the permission at any time in the iOS settings. Processing takes place within Apple's HealthKit policies: HealthKit data is not used for advertising and is not shared with third parties that are not processors within the scope of our service.

10. Sign in with Apple / Sign in with Google

When you log in with Apple or Google, the respective provider transmits to us only a stable identifier („sub“), your email address and (with Apple, once) your full name. We store the „sub“ to reliably recognize you on future logins. With Apple we additionally store a Fernet-encrypted refresh token that allows us to dissolve your link with Apple in the event of account deletion.

11. No automated decision-making within the meaning of Art. 22 GDPR

We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. The AI responses are supportive recommendations with no legally binding character.

12. Your rights

You have the right at any time to:

Access vs. portability — and what the in-app export contains: access (Art. 15 GDPR) is the broad right to a copy of everything we hold about you, including data we ourselves generated or observed (for example, our record of any administrator access to your account). Portability (Art. 20 GDPR) is narrower: only the data you provided us yourself, which we process by automated means on the basis of your consent or our contract with you, in a format you can take to another provider. In Settings, "Download data" gives you a structured JSON export that covers the right of access — your account details, your consent history, your profile, your food log, your burned-calories, your chat messages (including photo/audio metadata and their retention expiry, but never a signed file link or credential), your subscription/trial status, your AI usage, and the log of any administrator access to your account. This same export also satisfies portability for the subset of it you provided us under consent or contract. Anything beyond that export — a request in a different format, direct transmission to another controller, or a record we judge unsuitable for automatic disclosure (for example, one still under an open abuse or security investigation) — we handle manually by email.

For questions about these rights or to exercise them: [email protected].

13. Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for our seat is:
Berliner Beauftragte für Datenschutz und Informationsfreiheit, Alt-Moabit 59–61, 10555 Berlin, www.datenschutz-berlin.de.

14. Users in Switzerland (revFADP)

For users resident in Switzerland, the revised Swiss Federal Act on Data Protection (revFADP / revDSG, in force since 1 September 2023) applies in addition. Our GDPR-aligned processing meets its requirements in substance; the data-subject rights described in this policy (access, rectification, erasure) apply equally under the revFADP. The competent Swiss supervisory authority is the Federal Data Protection and Information Commissioner (FDPIC), Feldeggweg 1, 3003 Bern, www.edoeb.admin.ch.

15. Users in the United Kingdom (UK GDPR)

For users resident in the United Kingdom, the UK GDPR and the Data Protection Act 2018 apply in addition. Our GDPR-aligned processing meets their requirements in substance; the data-subject rights described in this policy apply equally. The competent supervisory authority for UK users is the Information Commissioner's Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF, ico.org.uk. Where we transfer UK personal data to the United States, we rely on the UK Extension to the EU-U.S. Data Privacy Framework ("UK-U.S. Data Bridge") for certified recipients, otherwise on the UK International Data Transfer Agreement (IDTA) or Addendum.

16. Users in New Zealand (Privacy Act 2020)

For users resident in New Zealand, the Privacy Act 2020 and its Information Privacy Principles apply in addition. Our processing meets its requirements in substance; the data-subject rights described in this policy (access, correction, deletion) apply equally. Our privacy officer for the purposes of the Act is Alexander Burkhard ([email protected]). The competent authority is the Office of the Privacy Commissioner (OPC), www.privacy.org.nz. Where we disclose personal information to providers outside New Zealand, we ensure comparable safeguards consistent with Information Privacy Principle 12.

17. Users in the United States

For users resident in the United States, the following applies in addition. We do not sell your personal information, and we do not share it for cross-context behavioral advertising — the service shows no ads and contains no advertising trackers. We treat health and nutrition data as sensitive personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA): we use it exclusively to provide the service you request, and not to infer characteristics about you for other purposes. Even where the applicability thresholds of individual US state privacy laws are not met, we extend their core rights — to know/access, correct, delete and port your data, without discrimination for exercising them — to all US users, as described in section 12. Requests: [email protected].

For consumers in Washington and Nevada, our separate Consumer Health Data Privacy Policy describes the consumer health data we process and the rights granted by the Washington My Health My Data Act (chapter 19.373 RCW) and Nevada's consumer health data law (SB 370, 2023), including withdrawal of consent, deletion and appeals.

California — CalOPPA "Do Not Track" disclosure: Dumb Calories does not perform cross-site behavioral tracking. The analytics on our public pages (home, /foods, /blog, described in section 7) are cookieless, pseudonymous, and scoped to the individual page visit or session — no cross-device identifier is set, our first-party relay (/relay) strips your visitor IP address before forwarding it to PostHog, and no third party is permitted to collect personal information about your activity over time and across other websites or apps through our service, or use it for cross-site advertising. You can opt out of that public-page analytics at any time via ?noph=1. Personalised in-app analytics run only if you consent to them in Settings. Because we do not sell or share personal information, a browser "Do Not Track" (DNT) signal or Global Privacy Control (GPC) signal does not trigger a sale/share opt-out on our service — there is no sale or share for it to opt out of.

18. Users in Canada

For users resident in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) applies in addition; for users in Quebec, also the Act respecting the protection of personal information in the private sector as modernized by Law 25. Our GDPR-aligned processing meets their requirements in substance: we process health and nutrition data only with your express consent, given at signup, and the rights described in this policy (access, correction, deletion, portability — including the data export in the app) apply equally. The person in charge of the protection of personal information (responsable de la protection des renseignements personnels) is Alexander Burkhard, founder ([email protected]).

Your data is stored and processed outside Canada — on servers in the European Union and, for the providers named in sections 4 and 5, in the United States and Switzerland. While there, it is subject to the laws of those jurisdictions and may be accessible to their courts, law-enforcement and national-security authorities. We remain accountable for it and protect it through the contractual and technical safeguards described in sections 4 and 5; for communications of Quebec users’ information outside Quebec we have carried out the written assessment required by section 17 of the Quebec Act. You can complain to us at any time, to the Office of the Privacy Commissioner of Canada (www.priv.gc.ca) or, in Quebec, to the Commission d’accès à l’information (www.cai.gouv.qc.ca). A French summary of this policy is available at Résumé en français.

19. Changes to this Privacy Policy

We reserve the right to adapt this Privacy Policy to changed legal or technical conditions. The current version is always available here; we will announce material changes with reasonable notice.